Description
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Remediation
References
Related Vulnerabilities
OpenSSL Out-of-bounds Read Vulnerability (CVE-2016-2180)
WordPress Plugin Custom Field Suite Cross-Site Request Forgery (2.5.15)
Piwigo Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-10680)
WordPress Plugin WP Hotel Booking Remote Code Execution (1.10.2)
Atlassian Jira Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-6619)